11/08/2026
📢 𝗡𝗲𝘄 𝗞𝗗𝗗𝗘 𝗽𝗮𝗽𝗲𝗿 𝗻𝗼𝘄 𝗼𝗻𝗹𝗶𝗻𝗲!
Can adversarial malware fool not only a detector, but also the explanation of its decision?
We are pleased to share our new paper:
𝗔𝗱𝘃𝗲𝗿𝘀𝗮𝗿𝗶𝗮𝗹 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗖𝗮𝗻 𝗕𝗲 𝗕𝗼𝘁𝗵 𝗘𝘃𝗮𝘀𝗶𝘃𝗲 𝗮𝗻𝗱 𝗗𝗲𝗰𝗲𝗶𝘃𝗶𝗻𝗴: 𝗮 𝗚𝗿𝗮𝗱𝗶𝗲𝗻𝘁-𝗯𝗮𝘀𝗲𝗱 𝗔𝘁𝘁𝗮𝗰𝗸 𝗔𝗴𝗮𝗶𝗻𝘀𝘁 𝗣𝗿𝗲𝗱𝗶𝗰𝘁𝗶𝗼𝗻 𝗮𝗻𝗱 𝗘𝘅𝗽𝗹𝗮𝗶𝗻𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗶𝗻 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝗣𝗘 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻
by Luca Lobascio, Giuseppina Andresini, Annalisa Appice, and Donato Malerba.
The paper introduces 𝗚𝗔𝗠𝗘𝟰𝗘𝗫𝗘, a gradient-based adversarial framework designed to pursue two goals at the same time: making Windows PE malware evade deep neural malware detectors and manipulating the corresponding explanations so that they resemble those of benign software.
This dual perspective — attacking both 𝗽𝗿𝗲𝗱𝗶𝗰𝘁𝗶𝗼𝗻 and 𝗲𝘅𝗽𝗹𝗮𝗻𝗮𝘁𝗶𝗼𝗻 — raises an important challenge for trustworthy AI in cybersecurity: securing model decisions may not be enough if the explanations used to understand those decisions can also be deceived.
The preliminary evaluation investigates GAME4EXE against two deep learning malware detectors, MalConv and BBDNN, exploring classification evasion, transferability, and the ability to produce goodware-like explanations.
📍 2026 IEEE 11th European Symposium on Security and Privacy Workshops (EuroS&PW)
🔗 𝗥𝗲𝗮𝗱 𝘁𝗵𝗲 𝗽𝗮𝗽𝗲𝗿 𝗼𝗻 𝗜𝗘𝗘𝗘 𝗫𝗽𝗹𝗼𝗿𝗲
DOI: 10.1109/EuroSPW72509.2026.00038
Research supported by FAIR – Future AI Research, Spoke 6 – Symbiotic AI, and SERICS under the NRRP MUR programme funded by the European Union – NextGenerationEU.